Analytics Informational

Remote account enumeration

Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Discovery (TA0007) Credential Access (TA0006)
ATT&CK techniques: Account Discovery (T1087) Brute Force (T1110)
Attacker's goals:

Discover valid accounts to gain credentials.

Investigative actions:

Check if the login attempts were part of a legitimate misunderstanding of the system or part of an attack.

Test period:
10 Minutes
Deduplication:
1 Day
2 variations:
  • Suspicious Remote domain account enumeration Medium (parent: Informational)
  • Remote account enumeration on domain accounts Low (parent: Informational)